Monday, April 16, 2007
Buying a car
Wholesale Values & Retail Values from Canada Red Book
Trade-in Price from Canadian Black Book
Kelley Blue Book Price
Auto Trader Canada Update every two week on Thursday
Edmuns Car Space
Canadian Driver
Auto Consumer Guide
MSN Auto Groups
http://www.repodepo.ca Auction Card
http://www.carfax.com/
Kanetix Insurance
StateFarm (416) 491-6333 (416) 493-3888
Johnson (416) 920-4421 1-877-406-9007
MTO UVIP
Discount Car Rental
Budget, National/Alamo, Hentz, Avis, Thrifty, Dollar-Rent-a-Car, Enterprise, Discount
Services
Oil Change
http://www.nscnetwork.com/en/thedeal.php 7634 Woodbine Ave, Unit 3B,Markham ON
http://www.oilchangers.ca/
Active green ross
Auxiliary Input Converter
Chevrolet Impala Lighting/Electrical Issues
http://www.logjamelectronics.com/auxgm.html
http://forums.genvibe.com/zerothread?id=22938
AUX2CAR
Soundgate AUXGMV3
PIE GM12-AUXV2
Wednesday, March 07, 2007
Useful Freeware
1. Image Tools
IrfanView a very fast, small, compact and innovative graphic viewer
Paint.Net free image and photo editing software
Photoshop CS2 sn: 1045-1412-5685-1654-6343-1431
Gadwin PrintScreen Excellent screen capture apps
Hugin an easy to use cross-platform panoramic imaging toolchain
@icon sushi Image to icon converter
2. Internet Tools
Firefox with some pulgin like Adblock Plus.
FileZilla 跨平台、开源软件,主要提供图形界面(GUI)的FTP支持,既有客户端,也有服务器功能,可以设定流量,支持断点续传,并支持IPv6, FTP over SSL/TLS (FTPS), SSH File Transfer Protocol (SFTP)。
uTorrent A Powerhouse With a Tiny Appetite, Speedy, efficient, and free BitTorrent client.
TeamViewer Remote control any computer or Mac over the internet
UltraVNC a powerful, easy to use and free software that can display the screen of another computer
Skype Calling, seeing, messaging and sharing with others – wherever they are.
HTTP File Server File sharing web server
Everything NTFS File search engine & File sharing
JDownloader It simplifies downloading files from One-Click-Hosters like Rapidshare.com or Megaupload.com. It offers downloading in multiple paralell streams, captcha recognition, automatical file extraction and much more.
3. Anti-Virus
Active Virus Shield
Active Virus Shield is brought to you as a free service of AOL and is based on Kaspersky Lab’s award winning Personal Anti-Virus.
Advanced Spyware Remover
Anti spyware tool that removes spyware, adware, malware, hijacker programs.
4. FireFox Plugin
Adblock Plus by Wladimir Palant Get rid of all those ads and banners on the internet.
FireBug by Joe Hewitt Firebug integrates with Firefox to put a wealth of development tools at your fingertips while you browse. You can edit, debug, and monitor CSS, HTML, and JavaScript live in any web page...
LastPass by LastPass.Com
LastPass is a password manager that makes web browsing easier and more secure..
5. System Tools
Hiren's BootCD 15.1 a completely free bootable CD that contains a load of useful tools
DriveImage XML backup any drive/partition to an image file, a very good alternative to Ghost / Acronis
Partition Wizard Free Partition Magic Alternative, Partition Resize/Move/Copy/Create/Delete/Format/Convert, Explore, etc.
Allway Sync File and folder synchronization software for Windows.
Notepad++ source code editor and Notepad replacement that supports several languages.
Notepad++ PluginManager plugin manager for Notepad++ editor.
ColorPic 4 Easily pick any color from the screen
DAEMON Tools Lite Most popular product that offers easy tools for making simple disc image files and emulating virtual CD/DVD drives.
Recuva File Recovery
Bullzip PDF Printer Easy, reliable PDF creation from all applications.
HJsplit file splitters
Truecrypt Free open-source disk encryption software for Windows 7/Vista/XP, Mac OS X, and Linux
DriverMax Allows you to download the latest driver updates for your computer.
Advanced Disk Cleaner Quickly find and wipe away all the garbage files on your computer.
Taskbar Button ManagerArrange the buttons on your Windows taskbar in any way you want by using drag and drop.
Unlocker
Tricks
1. Acdsee 6.0 freezed issue:
The reason of this problem is that maybe some of the database files (which are stored in ACDSee->Tools->Options->Database->Location) had been damaged, so the DBLocalServer freezed all the time. I resolved the problem by exiting from ACDSee and kill all DBLocalServer instance, and have been deleted all the files from the folder above (for me Document and Settings\...\Application Data\ACD Systems\Catalogs\Default).
Wednesday, February 07, 2007
美国迫使人民币升值的真正意图
80年代的“日本经济衰退”和90年代的“亚洲金融风暴”及“香港的香港金融保卫战”,也许有人会说那是国际投机集团“美国索罗斯财团”搞的,但是,你就没有想过它背后难道就没有美国政府的支持了吗?
从1980 开始的,特别在1990年和1995年,第一名的美国和第二名的日本之间的GDP差距是多少?日本GDP超过美国GDP的一半!这也是目前为止唯一一次其 它国家和美国的经济差距缩小到一半的程度。日本人在欢呼:只要超过美国的GDP,日本就可以恢复“正常国家”了!美国人没有吭声。
按理说,日本还是美国的盟国,其经济也是美国扶持起来的,美国也没有分裂日本的必要(要分裂,二战时就分裂了,也不用等到80-90年 代)。美国也不可能对盟国日本使用“颠覆性煽动”,眼看着美国是阻挡不了日本经济的发展前景的了!世界各国都在兴奋的期待着日本GDP超过美国GDP的那 个“历史性时刻”!日本企业更加疯狂,美国经济的象征----洛克菲勒广场被日本人买下了!美国的精神象征----好莱坞被日本人买了!美国人民的心情一 下子掉到了谷底。“世界第一”就快保不住了!美国人民的荣耀感在急剧下滑,民间开始蔓延仇日情绪。
1980年,日本的GDP就快到美国的一半了。有一件事情在1985年发生了,1985年美国拉拢其它五国(7国集团)逼迫日本签署 了。以“行政手段”迫使日元升值。其实的一个中心思想就是日本央行不得“过度”干预外汇市场。日本当时手头有充足的美元外汇储备,如果日本央行干预,日元 升不了值。可惜呀,日本是被去了势的太监。美国驻军、政治渗透、连宪法都是美国人帮它度身定做的,想不签广场协议都不可能。
日本最后的结局大家也知道了。1985年9月的广场协议至1988年初.美国要求日元升值。根据协议推高日元,日元兑美元的汇率从协议 前的1美元兑240日元上升到1986年5月时的1美元兑160日元。由于美国里根ZF坚持认为日元升值仍不到位,通过口头干预等形式继续推高日元。这 样,到1988年年初,日元兑美元的汇率进一步上升到1美元兑120日元,正好比广场协议之前的汇率上升了一倍
美国人满足了吗?没有。接着看下去,从1993年2月至1995年4月,当时克林顿ZF的财政部长贝茨明确表示,为了纠正日美贸易的不 均衡,需要有20%左右的日元升值,当时的日元汇率大致在1美元兑120日元左右,所以,根据美国ZF的诱导目标,日元行情很快上升到1美元兑100日 元。以后,由于克林顿 ZF对以汽车摩擦为核心的日美经济关系采取比较严厉的态度。到了1995年4月,日元的汇率急升至1美元兑79日元,创下历史最高记录。
日元升值的后果是什么?洛克菲勒广场重新回到了美国人手中,通用汽车在这个广场的一卖一买中净赚4亿美元!日资在艰难度日中大规模亏本 退出美国。美国人民胜利了!成功的击退了日本的经济进攻!我们可以从事例中看看1995年之后,日本和美国的GDP之比重新拉开了距离,而且越来越大!
可能有些网友还是没有明白,日元升值怎么啦?跟我们的谈论有什么关系?日元升值,就是美国对日本的一次经济阻击战!成功的把日本20多年的发展财富大转移到了美国去了。
下面我给个例子大家就清楚了。
假设我是美国财团,我当然知道1985会发生什么,假设我在1983年吧,我用100亿美元兑换成24000亿日元,进入日本市场,购买日 本股票和房地产,日本经济的蓬勃导致股市和房地产发疯一样的上涨,1985年广场协议签订,日元开始升值,到1988年初,股市和房地产假设我已经赚到了 一倍(5年才翻一倍是最低假设了),那就是48000亿日元。
这时,日元升值到1:120。我把日本的房地产和股票在一年中抛售完,然后兑换回美元,那么,就是400亿美元!在5年时间中,我净赚 300亿美元!(还是最低假设)。那么日本呢?突然离开的巨额外资就导致了日本经济的崩溃!经济学用词叫“泡沫经济破灭”。这就是日本常说的:“失去的十 年”。而我连本带利的400亿美元回到美国,你想一想,美国经济能不旺盛吗?!!日本“失去的十年”,却正是美国 “兴旺的十年”!看看我的上表就知道了。
我只是美国财团中的一个,其它财团呢?嘿嘿,而且我的假设还只是到1988年,如果是到1995年,日元升值到1:79,你我能想象美国在这场经济战争的胜利中,到底从日本刮走了多少财富?
美国赚够了,日元现在又重新回到了1:140的位置上,美元的坚挺依然和30年前一样!美元暂时性的贬值,并没有损害到美元的国际地位。这场美日的经济战争,以美国完胜而告终!!
美国人玩上瘾了。1998年,同样的手法在东南亚四小龙四小虎身上又来了一次,这就是亚洲金融风暴!唯一不同的,这次不需要广场协议了。因 为亚洲这些小虎小龙的外汇储备们直接阻击就可以大获全胜!但是,还是没有战胜财大气粗、军事强盛、奉行霸权主义的美国,结局大家也看到了,东南亚货币在先 升后跌中,经济发展的成果被美国抢掠一空!!
唯一市场硬挺住了索罗斯的进攻而没有经济崩溃的就只有回归后的香港,保住了香港几十年的发展果实。当时索罗斯发动世界舆论(包括香港舆 论),大肆攻击香港ZF(中国ZF)“行政干预市场”,违反市场经济规则、没有民主自由,要是当时中国屈服于世界的舆论压力而不运用“宏观调控”进行入市 干预,那将酿成大祸,又不知道要有多少国人向当年的日本那样因破产而跳楼自杀了!
当时的曾荫权后来说过:“决定ZF 入市干预的前一晚,我坐在床头哭了,不是为我自己,而是怕这个决定如果错误了,害了香港,我怎么向中央ZF向市民们交代。”大家现在知道为什么美国一再要 求他国“新闻自由”、“市场经济”、“民主人权”是建立在自己利益的基础上了吧,知道我国的“宏观调控”政策的正确性和优势所在了吧。
美国停手了吗?没有,因为我过综合势力的增长国力的增强威胁到了美国的根本利益和“世界第一”的权威,近来“中国公开支持因儿子丑闻陷 入困境的安南,指责美国故意借题发挥进行人生攻击。”就是最好的证明。所以美国心里就不痛快了,就要整人了,现在强迫人民币升值就是消弱中国的第一步,各 位明白了吗?知道为什么中央ZF突然狂力打压上海和北京的房地产市场?知道为什么中国股市那么惨了吗?央行行长周小川在3月还是4月曾说了一件事情:“有 一个40亿美元的外资在上海炒房地产,已经退出中国了这样的外资,不要也罢!”明白了吗?中国股市是一个弱势股市,很容易被美国财团利用。
中央不可能放松对股市的控制,否则中国经济将会在外资的攻击中崩溃!前段时间,也就是今年的12月初又有一个240亿美元的外资财团撤 离中国上海。现在,大家对国家的宏观调控的优势有所理解了吧,知道了国家出台那么多针对房地产的政策是多么的明智和及时了吧(文件详文附在后面,有兴趣的 可以读读)!
现在各位知道为什么中国要实行国家外汇管制、汇率控制、打压房地产、控制股市、知道为什么中国要保持巨额外汇储备,为什么最近央行又出台了新的房地产贷款规定,为什么中国ZF一直要求进出口贸易平衡,为什么要扩展东南亚贸易市场和欧盟市场,为什么要加WTO了。
其实中美之间的经济战争,早就已经开场了,而且来来回回过了几百招了。我们大多数网友还懵懵懂懂的只盯着台海,盯着中亚美军又多了一个军事 基地。要知道经济崩溃的灾难远比一场军事战争的后果更严重。军事战争不外乎两种:即“侵略战争”和“卫国战争”。而军事上的“侵略战争”的最终目的就是打 垮对方的一切(军事力量和经济实力)达到占领对方领土,进行资源掠夺和控制奴役和剥削对方的国民。
这样的事情中国历史上没有少发生,这里我就不例举事例了。而如今的美国就是以军事上的侵略战争为手段,达到奴役和剥削对方为目的的真实 意图(对实力弱小的国家而言),看看如今的“伊拉克”就明白了,美国实际上是侵略占领了伊拉克,控制了伊拉克的石油,以此来满足美国国内巨大的需求量;而 对实力强的原苏联(原苏联拥有制对方死地的核力量),美国就只有发动经济进攻来拖垮他们,苏联的分裂就是最好的例子。
也许有的人要说,那是冷战时期的军备竞赛和当时苏联国内政策导致了原苏联因经济崩溃而解体的。但是,你有没有想过,进行军备竞赛是以经 济实力为基础的。当时的美国经济实力比苏联强,所以,美国胜利了而苏联解体了。现在轮到我们了,我国现在的经济和军事实力都没有冷战时期的苏联强大,相同 点是我国同样也拥有毁灭美国的核武器,只是数量少了一点而已。那在这一轮中,就要看我国领导人的智慧了,建立合理的政策来规避风险,保护自己是当务之急 (可喜的是,现在我国已经在这样做了)。
可是,美国也没有闲着,而且,作为经济进攻的第一步他们已经早早的迈出了,向美国“凯雷财团”这样的世界性投机财团收购中国的“徐州重 工”这样的事情已经发生了很多了,在这里我就不一一例举了。他们的目的很明确,控制中国的核心技术,进行世界性的技术垄断,迫使量。同时乘汇率没有变化之 前以美元套取人民币,迫使中国央行大量发行人民币以应付大量的货币兑换需求,为拖垮中国经济打下伏笔。这还是明的进入,暗地里的就更无法统计了。
说到这里,也许有很多人不明白大量美元兑换人民币的行为与拖垮中国经济有什么关系。在这里,我解释一下:在没有大量美国财团恶意涌入中 国用大量美元换取人民币之前,我国的经济形式是相对稳定的,但是,实际上,我国发行的人民币的数量远没有我国人民积累的财富数量那么多,活动就行了,为印 刷货币的成本是很高的。
举个例子:中国有13亿人口,平均每人的财富拥有量为1 万元每人,中国总共有13万亿元财富,而现实生活中,每个人不可能把自己的全部财富都带在身上,这里就平均一下,平均每个人身上携带1000元现金(携带 量为10%,其实这个量已经是很大了),其余的存在银行,也就是说,在正常情况下的流动现金量(术语为:现金流量)为1千亿元,乘以一定的突变系数,(这 里为了便于计算,就理想的取值100%),也就是说在正常的经济活动下,中国只要发行2千亿人民币就可以满足本国的经济活动了。
Friday, February 02, 2007
Tuesday, November 28, 2006
Reset your XP/2003 password
2. Use ERD Commander 2005 , which is part of winternals's Administrator's Pak. Here it is a flash movie showing how to reset any password on local accounts on your PC including administrators.
3. In windows 2000, deleted "SAM" file under "\System32\Config" folder may allow you to login in with empty password. But this may result a system failure in windows xp and 2003 and cause the system been locked.
4. In windows 2000, if you have access to DOS, changed "logon.scr" under "\System32" to some other file name, and changed "cmd.exe" to "logon.scr", after reboot and wait several minute, you will bring to DOS screen where you can use "net user username userpassword/add" then "net localgroup administrators username/add" command to add a user. But in windows xp (sp2) and windows 2003, you do not have sufficient privilege to run "net user".
5. Use windowskey (part of "Passware Kit Enterprise") published by LostPassword.com.
It requied you burning a floppy driver disk. Then boot computer with windows xp setup cd and press F6 to load third party driver from floppy disk. This will reset administrator password to 12345.
6. Use DreamPackPL to create a bootable CD. Use this CD to boot computer and goto concole,
cd c:\windows\system32
ren sfcfiles.dll sfcfiles.lld
copy H:\i386\pinball.ex_ sfcfiles.dll
Here H is the CD. Then restart computer.
7. sysLinux. Download a image from here and burn it. Then load it up, it will start linux, then following these steps
- Disk select, tell which disk contains the Windows system. Optionally you will have to load drivers.
- PATH select, where on the disk is the system?
- File select, which parts of registry to load, based on what you want to do.
- Password reset or other registry edit.
- Write back to disk (you will be asked)
Create a bat file "admin.bat" under "C:\windows\system32\GroupPolicy\MachineScripts\Startup":
net user username userpassword/add
net localgroup administrators username/add
Create script file "scripts.ini" under "C:\windows\system32\GroupPolicy\MachineScripts":
[Startup]
0CmdLine=admin.bat
0Parameters=
Then reboot the computer.
9. Take out the dard disk and mount to another windows XP. Try to copy the "SAM" file under "\System32\Config" and run L0phtCrack or SAMInside to decrypt. Another way is overwrite this file with the SAM file from "\WINDOWS\repair\sam" folder will reset administrator to empty.
10. Some system tools:
Some other information about password recovery
323个精品小工具软件合集下载
CMOS Password Reset
Hiren's BootCD 8.6
BartPE
Windows7 USB DVD Tool
Format the thumb drive
- from a DOS prompt execute: diskpart
- list disk
- select disk 1 (assuming disk 1 was your thumb drive in the above list disk command)
- clean
- create partition primary
- select partition 1
- active
- format fs=fat32
- assign
- exit
- Insert your Windows Vista / 7 DVD into your drive.
- Change directory to the DVD’s boot directory where bootsect lives:
d:
cd d:\boot - Use bootsect to set the USB as a bootable NTFS drive prepared for a Vista/7 image. I’m assuming that your USB flash drive has been labeled disk G:\ by the computer:
bootsect /nt60 g:
导入KEY
C:\>slmgr.vbs -ipk *****-F8XX6-YG69F-9M66D-*****
导入证书
C:\>slmgr.vbs -ilc d:\hp.XRM-MS
看看是否成功啦
C:\>slmgr.vbs -dlv
Create the junction in NTFS:
mklink /J C:\Users\UserName D:\Users\UserName
Wednesday, November 22, 2006
Any way to create a span/mirror port on WRT54G router
First, the iptables is the most possible way to do this. 4Access mention there is a -tee switch on DD-WRT. So the following 2 lines can make this thing happen :
iptables -A PREROUTING -t mangle -s !192.168.0.0/24 -j ROUTE --gw
iptables -A POSTROUTING -t mangle -s !192.168.0.0/24 -j ROUTE --gw
Second, ettercap can perform ARP Spoofing , which may also achieve this goal.
My another thinking is use TCPDump on router and save the logs to share folder by Samba. Here has an article about how to use TCPDump.
Last but not least, try install Squid on a server to set up a proxy and doing log on this server may keep a histry for all HTTP accese. In router, force all HTTP request to this server by
To a different machine
iptables -t nat -A PREROUTING -i $INTERFACE -p tcp --dport 80 -j DNAT --to 10.0.3.1:8080
To the same machine
iptables -t nat -A PREROUTING -i $INTERFACE -p tcp --dport 80 -j REDIRECT --to-port 8080
Monday, November 20, 2006
iptables 实现Firewall,网址转换(NAT),数据包(package)记錄和流量统计
iptables [-t table] command [match] [target/jump]
1. 指定操作的表格(table)
-t 表格可以是filter,mangle,nat或者raw
2. 对链的操作(command):
链可以是PREROUTING、INPUT、FORWARD、POSTROUTING或者OUTPUT.
-A 加入(append) 一个新规则到一个链 (-A)的最后。
-I 在链内某个位置插入(insert) 一个新规则(-I),通常是插在最前面。
-R 在链内某个位置替换(replace) 一条规则 (-R)。
-D 在链内某个位置删除(delete) 一条规则 (-D)。
-L List
-F Flush, equivalent to deleting each rule one by one
-Z Zero, to zero all counters in a specific chain, or in all chains
-N New, create new chain
-X --delete-chain
-P --policy, set a specified default target, or policy, on a chain. All packets that don't match any rule will then be forced to use the policy of the chain
-E --rename-chain
操作Options
-v, --verbose gives verbose output and is mainly used together with the --list command
-x, --exact expands the numerics
-n, --numeric output numerical values
--line-numbers output line numbers.
-c, --set-counters initialize the packet and byte counters for the rule
--modprobe tell iptables which module to use when probing for modules or adding them to the kernel
3. match
1). 指定源地址和目的地址
-s/--src/--source 指定源地址
-d/--dst/--destination 指定目的地址
可以使用以下四中方法来指定ip地址:
a. 使用完整的域名,如“www.linuxaid.com.cn”;
b. 使用ip地址,如“192.168.1.1”;
c. 用x.x.x.x/x.x.x.x指定一个网络地址,如“192.168.1.0/255.255.255.0”;
d. 用x.x.x.x/x指定一个网络地址,如“192.168.1.0/24”这里的24表明了子网掩码的有效位数,这是 UNIX环境中通常使用的表示方法。
缺省的子网掩码数是32,也就是说指定192.168.1.1等效于192.168.1.1/32。
2). 指定网络接口
-i/--in-interface 指定进来的网络接口
-o/--out-interface 指定出去的网络接口
3). 指定协议及端口
-p/--protocol选项来指定协议
--sport/--source-port 指明源端口
--dport/--destination-port 指明目的端口
-f, --fragment match the second and third part of a fragmented packet
--tcp-flags match on the TCP flags in a packet, eg SYN,FIN,ACK SYN
-m addrtype addrtype match
--src-type match the source address type of the packet
--dst-type
4. target/jump
-j jump
范例
iptables -t nat -a PREROUTING -i ethl -p tcp - -dport 80 -j DNAT -- to -destination 192.168.1.3:8080
-t nat 操作nat 表格
-A PREROUTING 添加规则到指定表的PREROUTING链结
-i eth1 过滤条件: 从eth1界面进来的包
-p tcp 过滤条件:包格式符合tcp协议
--dport 80 过滤条件:目的端口为80
-j DNAT 处置目标: 跳到DNAT目标
-- to-destination 处置目标:将包的目的和端口 改成192.168.1.3:8080
How data travel to our own machine
| Step | Table | Chain | Comment |
|---|---|---|---|
| 1 | On the wire (e.g., Internet) | ||
| 2 | Comes in on the interface (e.g., eth0) | ||
| 3 | raw | PREROUTING | This chain is used to handle packets before the connection tracking takes place. It can be used to set a specific connection not to be handled by the connection tracking code for example. |
| 4 | This is when the connection tracking code takes place as discussed in the The state machine chapter. | ||
| 5 | mangle | PREROUTING | This chain is normally used for mangling packets, i.e., changing TOS and so on. |
| 6 | nat | PREROUTING | This chain is used for DNAT mainly. Avoid filtering in this chain since it will be bypassed in certain cases. |
| 7 | Routing decision, i.e., is the packet destined for our local host or to be forwarded and where. | ||
| 8 | mangle | INPUT | At this point, the mangle INPUT chain is hit. We use this chain to mangle packets, after they have been routed, but before they are actually sent to the process on the machine. |
| 9 | filter | INPUT | This is where we do filtering for all incoming traffic destined for our local host. Note that all incoming packets destined for this host pass through this chain, no matter what interface or in which direction they came from. |
| 10 | Local process or application (i.e., server or client program). |
How outgoing packets going from our own local host
| Step | Table | Chain | Comment |
|---|---|---|---|
| 1 | Local process/application (i.e., server/client program) | ||
| 2 | Routing decision. What source address to use, what outgoing interface to use, and other necessary information that needs to be gathered. | ||
| 3 | raw | OUTPUT | This is where you do work before the connection tracking has taken place for locally generated packets. You can mark connections so that they will not be tracked for example. |
| 4 | This is where the connection tracking takes place for locally generated packets, for example state changes et cetera. This is discussed in more detail in the The state machine chapter. | ||
| 5 | mangle | OUTPUT | This is where we mangle packets, it is suggested that you do not filter in this chain since it can have side effects. |
| 6 | nat | OUTPUT | This chain can be used to NAT outgoing packets from the firewall itself. |
| 7 | Routing decision, since the previous mangle and nat changes may have changed how the packet should be routed. | ||
| 8 | filter | OUTPUT | This is where we filter packets going out from the local host. |
| 9 | mangle | POSTROUTING | The POSTROUTING chain in the mangle table is mainly used when we want to do mangling on packets before they leave our host, but after the actual routing decisions. This chain will be hit by both packets just traversing the firewall, as well as packets created by the firewall itself. |
| 10 | nat | POSTROUTING | This is where we do SNAT as described earlier. It is suggested that you don't do filtering here since it can have side effects, and certain packets might slip through even though you set a default policy of DROP. |
| 11 | Goes out on some interface (e.g., eth0) | ||
| 12 | On the wire (e.g., Internet) |
How's the packet is destined for another host on another network
| Step | Table | Chain | Comment |
|---|---|---|---|
| 1 | On the wire (i.e., Internet) | ||
| 2 | Comes in on the interface (i.e., eth0) | ||
| 3 | raw | PREROUTING | Here you can set a connection to not be handled by the connection tracking system. |
| 4 | This is where the non-locally generated connection tracking takes place, and is also discussed more in detail in the The state machine chapter. | ||
| 5 | mangle | PREROUTING | This chain is normally used for mangling packets, i.e., changing TOS and so on. |
| 6 | nat | PREROUTING | This chain is used for DNAT mainly. SNAT is done further on. Avoid filtering in this chain since it will be bypassed in certain cases. |
| 7 | Routing decision, i.e., is the packet destined for our local host or to be forwarded and where. | ||
| 8 | mangle | FORWARD | The packet is then sent on to the FORWARD chain of the mangle table. This can be used for very specific needs, where we want to mangle the packets after the initial routing decision, but before the last routing decision made just before the packet is sent out. |
| 9 | filter | FORWARD | The packet gets routed onto the FORWARD chain. Only forwarded packets go through here, and here we do all the filtering. Note that all traffic that's forwarded goes through here (not only in one direction), so you need to think about it when writing your rule-set. |
| 10 | mangle | POSTROUTING | This chain is used for specific types of packet mangling that we wish to take place after all kinds of routing decisions have been done, but still on this machine. |
| 11 | nat | POSTROUTING | This chain should first and foremost be used for SNAT. Avoid doing filtering here, since certain packets might pass this chain without ever hitting it. This is also where Masquerading is done. |
| 12 | Goes out on the outgoing interface (i.e., eth1). | ||
| 13 | Out on the wire again (i.e., LAN). |
We have now seen how the different chains are traversed in three separate scenarios. If we were to figure out a good map of all this, it would look something like this:
链结
Linux核 心的包处理流程中,共设置了五个(鱼钩)拦截点(hook points),分别是PREROUTING、INPUT、FORWARD、POSTROUTING以及OUTPUT。內建链结只能作用在这些拦截点;你 可以针对个別拦截点设置一系列处理规则,每条规则各代表一次影响(或监测)包处理流程的机会。

表格(Tables)
iptables內建三个表格:filter、mangle以及nat每个表格都被预先设置了一或多个代表各拦截点的链结




包(package)的流程
当包流经链结时,必须依序通过该链结裡每一条规则的检验。若包符合某条规则的「筛选条件」(match),则将包交给该规则的「目标」(target)来 处理,否则,就继续由同链结裡的下一条规则予以检验。倘若包顺利通过链结裡的所有规则(不符合任何规则的筛选条件),则以链结的「政策」(policy, 参閱《链结(Chains)》来決定其去向。
包实际会经过哪些链结,取決於包本身的性质(转交、输入、输出、绕回),《表4》到《表7》分別列出各种性质的包的旅程顺序。《图1》《图2》和《图3》是单看特定筛表时,包如何通过该筛表各链结的详细流程。




规则(Rules)
iptables的每一条规则(rule),都是由两部分组成的,第一部分包含一或多个「过滤条件」其作用是检查包是否符合处理条件(所有条件都必须成立才算数) ;第而部分称为「目标」,用於決定如何处置符合条件的包。
过滤条件(Matches)
iptables可让你设置多种过滤条件,但是某些条件需要核心有提供相关功能才行。Iptables本身內建一般性的Internet Protocol (IP) 过滤条件,也就是說,即时沒载入任何扩充模组,你也可以用IP包标头的「传输协定类型」、「来源位址」、「目的地位址」等栏位为过滤条件。
目标(Target)
目标「(targets)决定如何处理符合过滤条件的包,或是当成链结的政策。iptables共内建四种目标ACCEP, DROP, QUEUE, RETURN

网址转译 (Network address translation,NAT)
NAT是一种涉及修改来源位址,目的地位址、来源端口、目的地端口之特殊「包修改」。对於只修改来源位址/通讯端口的操作,称为「Source NAT」(或简称为S-NAT或SN AT);若只修改目的地位址/通讯端口,则称为「Destination NAT」(或简称为D-NAT或DNAT)。某些形式的NAT需要运用「连線追蹤」来決定如何修改包。
偽装(Masquerading)
「偽装」是一种特殊的SNAT操作:将来自其它电脑的包的来源位址改成自己的位址:请注意,由於入替的来源位址是自动決定的(执行SNAT的主机的IP位 址)。所以,如果它改变了,仍在持续中的旧连線将会失效。「偽装」的主要用途是让多部使用private Ip的电脑(通常是透过DHCP动态取得)可以共用同一个public IP(固定或ISP动态分配)上网。
通讯埠转接(Port Forwarding)
「通讯埠转接」是一种特殊的DNAT操作,其作用是让一部电脑(通常是防火牆)担任其它电脑的代理伺服器(proxy)。防火牆接收外界网络接传给它自己 的包,然后改写包的目的地位址或目的端口,使其像是要送到內部网路其它电脑的樣子,然后才修改好的包送往新目的地。此外,来自內部网路的相关回复包,也会 被防火牆改写成像是从防火牆自己发出的樣子,然后才送到外界电脑。
其他iptables选项
-j option invokes a jump to one of the custom chains-L outputs the statistics for a chain-v option provides verbose output, including the packet and byte counters that we are interested in-n option as well to prevent DNS lookups, meaning iptables will show the IP addresses without attempting to resolve the hostnames for the IP addresses-save back up-restore restore
-c use the packet and byte counters